0Pricing
Edge Computing with Cloudflare Workers & Deno · レッスン

安全なシークレット管理

エッジ環境でAPIキー、トークン、その他の機密情報を安全に扱うためのベストプラクティスを学びます

「安全なシークレット管理」はCoddyKit上の無料Edge Computing with Cloudflare Workers & Denoレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはEdge Computing with Cloudflare Workers & Deno学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Edge Computing with Cloudflare Workers & Denoコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

What Are Edge Secrets?

When building applications, especially at the edge, you often need to handle sensitive information. These are called secrets.

Secrets include things like API keys, database credentials, authentication tokens, and private encryption keys. They are critical for your application's security and functionality.

Dangers of Hardcoding Secrets

A common mistake, especially for beginners, is to hardcode secrets directly into your application's source code.

  • Exposure: Anyone with access to your code (e.g., in a public Git repository) can see your secrets.
  • Rotation Issues: Changing a secret means changing and redeploying your code everywhere it's used.
  • Security Breach: A single leak can compromise your entire system.

Cloudflare Worker Environment Variables

Cloudflare Workers provide a secure way to manage secrets using environment variables. These variables are:

  • Injected securely at runtime, not stored in your code.
  • Encrypted at rest by Cloudflare.
  • Specific to each Worker, allowing fine-grained control.

They are accessed via the env object in your Worker's fetch handler.

Accessing Worker Secrets Demo

This Worker accesses an environment variable named MY_API_KEY. Notice how the secret itself is never hardcoded in the script.

Try running it! (The actual key won't be shown for security).

export default {
  async fetch(request, env, ctx) {
    const apiKey = env.MY_API_KEY; // Access the secret

    if (apiKey) {
      return new Response(`Secret accessed! Length: ${apiKey.length}`);
    } else {
      return new Response(
        "MY_API_KEY environment variable not set.",
        { status: 400 }
      );
    }
  },
};

Deno Environment Variables

Similar to Workers, Deno applications also use environment variables for secrets. You can access them using Deno.env.

For local development, you might use .env files (though not directly supported by Deno, tools like deno task or third-party modules can help). For Deno Deploy, secrets are configured securely through their platform UI or CLI.

Using Deno Secrets Demo

Here's a simple Deno script that retrieves a secret named DB_PASSWORD from its environment variables. Run this example to see it in action.

const dbPassword = Deno.env.get("DB_PASSWORD");

if (dbPassword) {
  console.log(`Database password accessed. Length: ${dbPassword.length}`);
} else {
  console.log("DB_PASSWORD environment variable not set.");
  console.log("To set: env DB_PASSWORD='mysecret' deno run --allow-env main.ts");
}

Managing Secrets with Wrangler CLI

For Cloudflare Workers, the Wrangler CLI is your go-to tool for managing secrets. It encrypts and securely uploads them to Cloudflare's infrastructure.

  • wrangler secret put <NAME>: Prompts for a secret value and uploads it.
  • wrangler secret delete <NAME>: Removes a secret.
  • wrangler secret list: Lists all secrets for your Worker.

This keeps secrets out of your wrangler.toml file and source code.

Principle of Least Privilege

A crucial security principle is the Principle of Least Privilege. This means:

  • Granting only the minimum necessary permissions to access resources.
  • Only giving access to secrets to the specific services or users that absolutely need them.

Avoid giving a Worker access to a secret it doesn't actually use, even if it seems convenient.

Secret Rotation and Auditing

Even with secure storage, secrets can be compromised. Implement these practices:

  • Secret Rotation: Regularly change your API keys and tokens (e.g., every 90 days). This limits the window of opportunity for attackers if a secret is leaked.
  • Auditing: Monitor and log access to your secrets. This helps detect unusual activity and potential breaches.

Automate these processes where possible to reduce manual overhead.

Secrets Management Check

Test your understanding of secure secrets management.

Recap: Secure Secrets

In this lesson, we learned about the importance of securely managing sensitive information in edge applications.

  • Never hardcode secrets.
  • Utilize platform-provided environment variables (Cloudflare Workers env, Deno Deno.env).
  • Use tools like Wrangler CLI for secure secret deployment.
  • Follow the Principle of Least Privilege.
  • Implement regular secret rotation and auditing.

These practices are fundamental to building robust and secure edge applications.

よくある質問

「安全なシークレット管理」レッスンは無料ですか?

はい。「安全なシークレット管理」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Edge Computing with Cloudflare Workers & Denoコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Edge Computing with Cloudflare Workers & Denoコースには全4レッスンが含まれています。

「安全なシークレット管理」で何を学びますか?

エッジ環境でAPIキー、トークン、その他の機密情報を安全に扱うためのベストプラクティスを学びます ブラウザで直接実行するハンズオンコードでEdge Computing with Cloudflare Workers & Denoを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Edge Computing with Cloudflare Workers & Denoを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのEdge Computing with Cloudflare Workers & Denoは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。

「安全なシークレット管理」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このEdge Computing with Cloudflare Workers & Denoレッスンでコードを書いて実行できますか?

はい。すべてのEdge Computing with Cloudflare Workers & Denoレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. 認証と認可
  2. レート制限とDDoS対策
  3. 安全なシークレット管理
  4. 入力サニタイズとインジェクション対策
← Edge Computing with Cloudflare Workers & Denoに戻る